Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, September 8, 2012

Java does a “Jack and Jill”

Posted on 9:35 AM by Unknown

CC attribution: illustration "Jack and Jill" by "perpetualplum" on flickr.
Jack n Jill Mod

So here is the way I saw the Java drama roll downhill like Jack and Jill over the last two weeks from security standpoint.

So we started out safely headed up the hill to fetch our water shod with Oracle’s Java 1.7 update 6.

08/27/2012 - Starting up the hill…

  • Quick Bits about Today's Java 0-Day - ISC Diary
  • Research & Analysis of Zero-Day & Advanced Targeted Threats:Zero-Day Season is Not Over Yet - Malware Intelligence Lab from FireEye
  • Java 7 0-Day vulnerability information and mitigation - DeepEnd Research
  • Attackers Pounce on Zero-Day Java Exploit - Krebs on Security
  • Researchers: Java Zero-Day Leveraged Two Flaws - Krebs on Security

Oh noes! Jack has stumbled!

(It wasn’t really clear at first, but Java 1.6.34 was also vulnerable.)

08/30/2012 - Java Jack Recovers

Fortunately Java Jack just had a stumble, the pail and his crown are still safe after catching himself.

  • Oracle Releases Java Security Updates - ISC Diary
  • Vulnerability Note VU#636312 - Oracle Java JRE 1.7 Expression.execute() and SunToolkit.getField() fail to restrict access to privileged code - US-CERT
  • Alert for CVE-2012-4681 - Oracle
  • Java SE 7u7 AND SE 6u35 Released - F-Secure Weblog : News from the Lab
  • Oracle patches critical Java bugs used to commandeer computers -  Ars Technica

So we all rush out and download Java 1.7.7 and/or Java 1.6.35.

Whew! That was close.

08/31/2012 - Java Jack Takes a Dive bringing Jill with him

Jack…Stop looking at that frisky rabbit and getting ideas and pay attention dude! You’re about to step into some of its…

Oh snap! You did and you slipped in it.

  • Not so fast: Java 7 Update 7 critical vulnerability discovered in less than 24 hours - ISC Diary
  • Critical bug in newest Java gives attackers complete control of PCs - Ars Technica
  • Latest Java sandbox is still vulnerable - The H Security: News and Features
  • Blackhole targeting Java vulnerability via fake Microsoft Services Agreement email phish - ISC Diary

Seriously Jack. Really?

You should have been paying better attention to your hill-climbing technique; or at the very least dear Jill and not the rabbit.

Now you’ve taken Jill out in your folly and broken your crown; again.

Still Want That Water?

So where does that leave us now that we are holding the pail to safely quench our thirst?

Here is some sound advice.

  • 6 ways to protect against the new actively exploited Java vulnerability - Security - InfoWorld
  • You don't need Java - BetaNews
  • Tips For Java Junkies - F-Secure Weblog : News from the Lab

Me? I just disabled my Java browser plugins for IE/Chrome/Firefox and run NoScript in Firefox. However I didn’t uninstall my Java applications (1.6.35/1.7.6) as I do use a handful of true Java applications on my system.

I figure that will have to do for now until the next round of updates rolls.

No word when Jack will be out of the ER yet. Jill remains pouty.

Other Java-related tools you might be interested in while you wait…

  • JavaRa - SingularLabs - great third-party freeware utility to manage your Java RE build installations. More here at ghacks.net.
  • Jarfix - Johann N. Löfflmann’s tiny app to fix Java “JAR” file associations on Windows after a Java update borks them.
  • Java SE Downloads - Oracle - Java SE (Standard Edition) 7u7 JRE (Java Runtime Environment) and Java SE 6 update 35 JRE download links available from this link. When new updates are available you should be able to get them here.

Oh, did I mention that we just completed a massive rollout of Java 1.6.31 a few weeks ago across our enterprise to bring us to a new operational standard?

I lovingly refer to it as Project Maginot Line.

à revoir! from the bunker,

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in browsers, Chrome/Chromium, Firefox, Internet Explorer, security, utilities, viruses | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Lego MiniFig Extravaganza
    picture clipped from Wired’s clip from Gizmodo clip… Thanks in no small part to the Windows 7 RC release, XPM mode research, and a big “l...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ▼  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ▼  September (8)
      • Windows 8 Linkage: A Bit Behind the Ball
      • Scratching at a SCSI Drive Itch - Part II - WinPE ...
      • Scratching at a SCSI Drive Itch - Part I - Hello U...
      • Network Miner Updating on Ubuntu 12.04
      • MetroTextual - Spirit of the notepad known as Bend
      • Java does a “Jack and Jill”
      • Trouble with The TEDinator
      • A Little Bit All Over the Place
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile